What is CVE-2026-73354?
This vulnerability allows an Unauthenticated Cross Site Scripting (XSS) attack in SimplyRETS Real Estate IDX plugin versions 3.2.8 and below. An attacker can inject malicious scripts without authentication, compromising website security. Upgrading to the latest version is strongly recommended.
Azərbaycanca: Bu zəiflik SimplyRETS Real Estate IDX plagininin 3.2.8 və daha köhnə versiyalarında autentifikasiya olmadan Cross Site Scripting (XSS) hücumuna imkan verir. Təcavüzkar istifadəçi girişi olmadan zərərli skript icra edə bilər, bu da saytın təhlükəsizliyini riskə atır. Plagini ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Which versions of the SimplyRETS Real Estate IDX plugin are affected by CVE-2026-73354?
This vulnerability affects SimplyRETS Real Estate IDX plugin versions 3.2.8 and below.
What is the primary recommendation to protect against CVE-2026-73354?
To ensure website security, it is strongly recommended to upgrade the SimplyRETS Real Estate IDX plugin to the latest version.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.